Vulnerabilities > Deltascripts

DATE CVE VULNERABILITY TITLE RISK
2006-10-10 CVE-2006-5208 SQL Injection vulnerability in Deltascripts PHP Classifieds 7.1
Multiple SQL injection vulnerabilities in PHP Classifieds 7.1 allow remote attackers to execute arbitrary SQL commands via (1) the catid_search parameter in search.php and (2) the catid parameter in index.php.
network
low complexity
deltascripts
7.5
2006-06-30 CVE-2006-3330 Input Validation vulnerability in Deltascripts PHP Classifieds 6.04
Cross-site scripting (XSS) vulnerability in AddAsset1.php in PHP/MySQL Classifieds (PHP Classifieds) allows remote attackers to execute arbitrary SQL commands via the (1) ProductName ("Title" field), (2) url, and (3) Description parameters, possibly related to issues in add1.php.
network
deltascripts
6.8
2006-06-30 CVE-2006-3329 Input Validation vulnerability in Deltascripts PHP Classifieds 6.04
SQL injection vulnerability in search.php in PHP/MySQL Classifieds (PHP Classifieds) allows remote attackers to execute arbitrary SQL commands via the rate parameter.
network
low complexity
deltascripts
7.5
2006-06-07 CVE-2006-2876 Cross-Site Scripting vulnerability in PHP Pro Publish
Cross-site scripting (XSS) vulnerability in cat.php in PHP Pro Publish 2.0 allows remote attackers to inject arbitrary web script or HTML via the catname parameter.
network
deltascripts
6.8
2006-06-05 CVE-2006-2821 Cross-Site Scripting vulnerability in Deltascripts PRO Publish 2.0
Multiple cross-site scripting (XSS) vulnerabilities in DeltaScripts Pro Publish allow remote attackers to inject arbitrary web script or HTML via the (1) artid parameter in art.php and the (2) catname parameter in cat.php.
network
deltascripts
6.8
2006-06-03 CVE-2006-2803 Cross-Site Scripting vulnerability in Deltascripts PHP Manualmaker 1.0
Multiple cross-site scripting (XSS) vulnerabilities in PHP ManualMaker 1.0 allows remote attackers to inject arbitrary web script or HTML via the (1) id parameter to index.php, (2) search field (possibly the s parameter), or (3) comment field.
6.8
2006-05-01 CVE-2006-2129 SQL Injection vulnerability in Deltascripts PRO Publish 2.0
Direct static code injection vulnerability in Pro Publish 2.0 allows remote authenticated administrators to execute arbitrary PHP code by editing certain settings, which are stored in set_inc.php.
network
low complexity
deltascripts
5.5
2006-05-01 CVE-2006-2128 SQL Injection vulnerability in Deltascripts PRO Publish 2.0
Multiple SQL injection vulnerabilities in Pro Publish 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) email and (2) password parameter to (a) admin/login.php, (3) find_str parameter to (b) search.php, or (4) artid parameter to (c) art.php, or (5) catid parameter to (d) cat.php.
network
low complexity
deltascripts CWE-89
7.5
2006-03-30 CVE-2006-1532 Cross-Site Scripting vulnerability in Deltascripts PHP Classifieds 6.18/6.20
Cross-site scripting (XSS) vulnerability in search.php in PHP Classifieds 6.18, 6.20, and possibly other versions, allows remote attackers to inject arbitrary web script or HTML via the searchword parameter.
network
deltascripts
4.3
2006-02-15 CVE-2006-0719 SQL Injection vulnerability in Deltascripts PHP Classifieds 6.18/6.19/6.20
SQL injection vulnerability in member_login.php in PHP Classifieds 6.18 through 6.20 allows remote attackers to execute arbitrary SQL commands via the (1) username parameter, which is used by the E-mail address field, and (2) password parameter.
network
low complexity
deltascripts
7.5